1-6
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Profiles, Group Policies, and Users
Configuring Connection Profiles
Configuring Connection Profiles
This section describes the contents and configuration of connection profiles in both single context mode
or multiple-context mode:
Note
Multiple-context mode applies only to IKEv2 and IKEv1 site to site and does not apply to AnyConnect,
Clientless SSL VPN, legacy Cisco VPN client, the Apple native VPN client, the Microsoft native VPN
client, or cTCP for IKEv1 IPsec.
•
Maximum Connection Profiles, page 70-6
•
Default IPsec Remote Access Connection Profile Configuration, page 70-7
•
Specifying a Name and Type for the Remote Access Connection Profile, page 70-8
•
Configuring Remote-Access Connection Profiles, page 70-8
•
Configuring LAN-to-LAN Connection Profiles, page 70-17
•
Configuring Connection Profiles for Clientless SSL VPN Sessions, page 70-20
•
Customizing Login Windows for Users of Clientless SSL VPN Sessions, page 70-27
•
Configuring the Connection Profile for RADIUS/SDI Message Support for the AnyConnect Client,
page 70-34
You can modify the default connection profiles, and you can configure a new connection profile as any
of the three tunnel-group types. If you do not explicitly configure an attribute in a connection profile,
that attribute gets its value from the default connection profile. The default connection-profile type is
remote access. The subsequent parameters depend upon your choice of tunnel type. To see the current
configured and default configuration of all your connection profiles, including the default connection
profile, enter the
show running-config all tunnel-group
command.
Maximum Connection Profiles
The maximum number of connection profiles (tunnel groups) that an ASA can support is a function of
the maximum number of concurrent VPN sessions for the pl 5. For example, an ASA 5505 can
support a maximum of 25 concurrent VPN sessions allowing for 30 tunnel groups (25+5). Attempting
to add an additional tunnel group beyond the limit results in the following message: “ERROR: The limit
of 30 configured tunnel groups has been reached.”
Table 70-2
specifies the maximum VPN sessions and connection profiles for each ASA platform.
override-svc-download
Overrides downloading the group-policy or username attributes
configured for downloading the AnyConnect VPN client to the remote
user.
radius-reject-message
Enables the display of the RADIUS reject message on the login screen
when authentication is rejected.
Table 1-1
Connection Profile Attributes for SSL VPN (continued)
Command
Function
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......